xsspresso
xsspresso
Tags/ API

API

2 writeups tagged with API

MiscMediumLinux

HTB — Mentor

SNMP v3 credential brute-force yields API secret. Command injection in backup API endpoint. PostgreSQL password enables lateral movement and sudo root.

#SNMP#Command Injection#API
Jan 15, 2025HackTheBox
WebMediumLinux

HTB — Node

Node.js API endpoint exposes hashed admin credentials. MongoDB backup decryption and SUID binary analysis for root.

#Node.js#MongoDB#API
Apr 5, 2022HackTheBox